This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] browser hijack? memory problems, internet problems, comp

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here's a brief summary of my problems: the computer has been going much, much slower than usual. it often freezes on the 'sleep mode' screen. firefox freezes if there is a download going and i am using the browser at the same time. often, when i am browsing the web, half of the pictures on the website will load and then it will just keep loading forever. every so often, it will say 'server cannot be found' and i have to refresh it. it usually comes up, then. the BSOD has come up twice, and there is a "low memory" message that comes up often. this computer is brand new! please help.

a new problem is that, whenever it goes into standby, it freezes. or whenever the screen turns back, the whole computer freezes. i've temporarily solved this by disabling standby and choosing to keep the monitor on forever.

***also, i've posted this on three other tech support forums, and there has been no response even though i posted it much over a week ago and did all the necessary procedures for "no response" situations. i understand people on these sites are busy, but i'd really appreciate it if at least one person tried to help me, please. ._.***

edit: here is an error i just got:

C:\DOCUME~1\bink\LOCALS~1\Temp\WER61f9.dir00\mDNSResponder.exe.mdmp
C:\DOCUME~1\bink\LOCALS~1\Temp\WER61f9.dir00\appcompat.txt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:46:53 PM, on 7/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinBar\WinBar.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: WinBar.lnk = C:\Program Files\WinBar\WinBar.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {E6BB2089-163F-466B-812A-748096614DFD} (CAScanner Control) - http://cainternetsecurity.net/scanner/cascanner.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5D2AEB3-BBDB-4883-9379-55038DCB760D}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 8290 bytes
Hi faburizu,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please notify the other forums that you are being helped here and close your topics there.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
thank you, thank you, thank you for responding! i have been pulling my hair out over this problem for so long.
i've been using MBAM for a long time now, and running scans almost every day.

here are my computer's CURRENT symptoms:
i tested my comupter by attempting to download a large, safe file of about >300MB.
the moment the file began download, the entire computer slowed.
firefox went into (not responding) and my memory on winbar kept saying 890-894/894MB. i pressed ctrl+alt+del to end firefox.exe
i also had aim.exe open, which slowed and eventually froze as well, so i ctrl+alt+del again
and AVGNSX.exe running at least 30K+, so ended that and aim.exe unfroze.
i opened My Computer, which took about 45-60 seconds, which is unusually slow
i quickly opened hijackthis, hoping that it would catch whatever is making my computer go like this, and halfway through scanning
a message came up that said another application was running and it could not continue,
but about 15 seconds later, that went away and it finished.

i've scanned my computer with panda activescan, avg, mbam, spybot search&destroy, adaware, superantispyware, ccleaner and a bunch of other programs.
it either finds an item and quarentines/removes it, or doesn't find anything.
this is driving me CRAZY./




here are the scan results:

Malwarebytes' Anti-Malware 1.38
Database version: 2373
Windows 5.1.2600 Service Pack 3

7/15/2009 2:53:24 AM
mbam-log-2009-07-15 (02-53-24).txt

Scan type: Quick Scan
Objects scanned: 101777
Time elapsed: 5 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:56 AM, on 7/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinBar\WinBar.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…mp;m=el1200-06w
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Startup: WinBar.lnk = C:\Program Files\WinBar\WinBar.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {E6BB2089-163F-466B-812A-748096614DFD} (CAScanner Control) - http://cainternetsecurity.net/scanner/cascanner.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5D2AEB3-BBDB-4883-9379-55038DCB760D}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 8220 bytes
faburizu,

I'm going to have you run one more scan, but I seriously think it's not going to find any malware. Don't fret though because if that turns out to be the case, we have an excellent Tech Team here that can probably help.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
okay, what do i do from here? :wacko:



Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully …
.
Windows XP Home Edition (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 127 Stepping 2, AuthenticAMD
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Disabled !
.
Internet Explorer 7.0.5730.13
Mozilla Firefox 3.5 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:69 Go - Free:30 Go )
D:\ [Fixed-NTFS] .. ( Total:69 Go - Free:68 Go )
F:\ [CD_Rom]
G:\ [Removable]
I:\ [Fixed-FAT32] .. ( Total:465 Go - Free:356 Go )
.
Scan : 15:47.33
Path : C:\Documents and Settings\bink\My Documents\Downloads\Rooter.exe
User : bink ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (680)
______ \??\C:\WINDOWS\system32\csrss.exe (764)
______ \??\C:\WINDOWS\system32\winlogon.exe (788)
______ C:\WINDOWS\system32\services.exe (832)
______ C:\WINDOWS\system32\lsass.exe (844)
______ C:\WINDOWS\system32\svchost.exe (1008)
______ C:\WINDOWS\system32\svchost.exe (1056)
______ C:\WINDOWS\System32\svchost.exe (1152)
______ C:\WINDOWS\system32\svchost.exe (1224)
______ C:\WINDOWS\system32\svchost.exe (1308)
______ C:\WINDOWS\Explorer.EXE (1884)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (1984)
______ C:\WINDOWS\system32\spoolsv.exe (624)
______ C:\WINDOWS\system32\svchost.exe (468)
______ C:\WINDOWS\system32\agrsmsvc.exe (520)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (636)
______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (648)
______ C:\Program Files\Bonjour\mDNSResponder.exe (668)
______ C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (720)
______ C:\Program Files\Common Files\LightScribe\LSSrvc.exe (1252)
______ C:\Program Files\LogMeIn\x86\RaMaint.exe (1684)
______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (1708)
______ C:\Program Files\LogMeIn\x86\LogMeIn.exe (1916)
______ C:\Program Files\LogMeIn\x86\LMIGuardian.exe (2144)
______ C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (2196)
______ C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (2272)
______ C:\WINDOWS\system32\nvsvc32.exe (2284)
______ C:\PROGRA~1\AVG\AVG8\avgemc.exe (2380)
______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (2604)
______ C:\WINDOWS\system32\wbem\unsecapp.exe (3204)
______ C:\WINDOWS\System32\alg.exe (3212)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (3420)
______ C:\WINDOWS\RTHDCPL.EXE (3500)
______ C:\WINDOWS\system32\ctfmon.exe (3536)
______ C:\Program Files\WinBar\WinBar.exe (4028)
______ C:\WINDOWS\System32\svchost.exe (4036)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (1544)
______ C:\Program Files\AIM\aim.exe (2084)
______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (3864)
______ C:\Program Files\Windows Live\Messenger\msnmsgr.exe (2120)
______ C:\Program Files\Windows Live\Contacts\wlcomm.exe (1968)
______ C:\Program Files\Mozilla Firefox\firefox.exe (1620)
______ C:\Documents and Settings\bink\My Documents\Downloads\Rooter.exe (2176)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:10478974464)
\Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:10479006720 | Length:74521036800)
\Device\Harddisk0\Partition3 (Start_Offset:85000043520 | Length:75039229440)
.
———————-\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
.
———————-\\ Registry
.
.
———————-\\ Files & Folders
.
C:\DOCUME~1\bink\My Documents\GameHouse\mah jong medley\Mah_Jong_Medley_2.0_crack.exe
==> Cracks & Keygens <==
.
———————-\\ Scan completed at 15:47.42
.
C:\Rooter$\Rooter_1.txt - (15/07/2009 | 15:47.42).c
faburizu,

The good news is, we didn't find any rootkits. The bad news is you download cracks. This behavior is not only illegal, it virtually guarantees you to get infected.

We're going to take care of the crack and then I'm going to have you do an online scan to see if we can find where the little bugger is hiding.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    C:\DOCUME~1\bink\My Documents\GameHouse\mah jong medley\Mah_Jong_Medley_2.0_crack.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
I've posted the OTM log, however when tried running the Kapersky scan on Firefox AND IE, it gives me the following error message: "Starting Java applet has failed. Please go online to use this program." On IE, a security warning also came up that said it was blocked because it was from an unknown publisher or something. This happened when downloading the Java. All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== C:\DOCUME~1\bink\My Documents\GameHouse\mah jong medley\Mah_Jong_Medley_2.0_crack.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: bink File delete failed. C:\Documents and Settings\bink\Local Settings\Temp\~DF4682.tmp scheduled to be deleted on reboot. ->Temp folder emptied: 751035 bytes File delete failed. C:\Documents and Settings\bink\Local Settings\Temporary Internet Files\Content.IE5\X31LI6ZY\AIM_text[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\bink\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 669514 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 44698683 bytes ->Opera cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes File delete failed. C:\WINDOWS\temp\$$$dq3e scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\$$yt7.$$ scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\$67we.$ scheduled to be deleted on reboot. Windows Temp folder emptied: 139935 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 44.24 mb OTM by OldTimer - Version 3.0.0.5 log created on 07152009_163201 Files moved on Reboot… C:\Documents and Settings\bink\Local Settings\Temp\~DF4682.tmp moved successfully. C:\Documents and Settings\bink\Local Settings\Temporary Internet Files\Content.IE5\X31LI6ZY\AIM_text[1].htm moved successfully. File move failed. C:\WINDOWS\temp\$$$dq3e scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\$$yt7.$$ scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\$67we.$ scheduled to be moved on reboot. Registry entries deleted on Reboot…
faburizu,

Give this a try.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 14

Then try Kaspersky. If no go, then let me know and we will do something different.
looks like we found something! ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Thursday, July 16, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, July 15, 2009 23:09:34 Records in database: 2472541 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ F:\ G:\ I:\ Scan statistics: Files scanned: 133321 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 03:35:26 File name / Threat name / Threats count C:\System Volume Information\_restore{04B20ACC-AE7D-4F34-B547-573C2828457F}\RP42\A0026158.dll Infected: Trojan.Win32.Genome.hmr 1 The selected area was scanned.
faburizu,

What you have there is another good news, bad news situation. The good news is that what Kaspersky found is in System Restore and we are going to clean that out. The bad news is that if you didn't have the infection at some point, it wouldn't be in your system restore point. And the continued bad news is:

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.


To make sure we've got it all, I'd like to bring in the big gun.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Trust me, I would love to have my harddrive wiped and Windows reinstalled, however I don't have a Windows XP CD, and therefore I cannot. I ran combofix, though.

ComboFix 09-07-14.08 - bink 07/16/2009 0:45.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.478 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1314201555-3785290187-2462946864-1006
c:\windows\APanel.exe
c:\windows\Installer\7e82.msi
c:\windows\Installer\b342.msi
I:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.

2009-07-15 23:49 . 2009-07-15 23:49 ——– d—–w- c:\program files\JavaFX
2009-07-15 23:45 . 2009-07-15 23:45 ——– d—–w- c:\program files\Sun
2009-07-15 23:44 . 2009-07-15 23:44 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-07-15 21:32 . 2009-07-15 21:32 ——– d—–w- C:\_OTM
2009-07-15 20:47 . 2009-07-15 20:47 ——– d—–w- C:\Rooter$
2009-07-14 14:18 . 2009-07-14 14:18 ——– d—–w- c:\documents and settings\All Users\Application Data\AWEM
2009-07-14 14:18 . 2009-07-14 14:18 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\DFH
2009-07-12 22:52 . 2009-07-12 22:53 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-12 22:52 . 2009-07-12 22:52 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-07-12 22:08 . 2009-07-12 22:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-12 13:33 . 2009-06-18 23:50 327688 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-12 13:33 . 2009-06-18 23:50 337176 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglogx.dll
2009-07-12 13:33 . 2009-06-18 23:50 3298072 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-12 13:33 . 2009-06-18 23:50 3402008 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-12 13:33 . 2009-06-18 23:50 829208 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-12 13:33 . 2009-06-18 23:50 1204504 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-12 13:33 . 2009-06-18 23:50 2167576 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-12 13:33 . 2009-06-18 23:50 906520 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgemc.exe
2009-07-12 13:32 . 2009-06-18 23:50 1085208 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-12 13:32 . 2009-06-18 23:50 1454360 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-07-12 00:11 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-12 00:04 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-12 00:03 . 2009-07-12 00:03 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-12 00:03 . 2009-07-08 17:28 2920112 -c–a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-07-12 00:03 . 2009-07-12 00:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-12 00:03 . 2009-07-12 00:03 ——– d—–w- c:\program files\Lavasoft
2009-07-11 22:41 . 2009-07-13 01:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-11 22:41 . 2009-07-11 22:43 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-11 20:01 . 2008-06-19 22:24 28544 —-a-w- c:\windows\system32\drivers\pavboot.sys
2009-07-11 20:00 . 2009-07-11 20:00 ——– d—–w- c:\program files\Panda Security
2009-07-11 19:48 . 2009-07-11 19:48 ——– d—–w- c:\documents and settings\All Users\Application Data\CA
2009-07-11 19:10 . 2009-07-11 19:10 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-11 19:10 . 2009-07-11 19:10 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-11 04:25 . 2009-07-11 06:55 117760 —-a-w- c:\documents and settings\bink\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-11 04:25 . 2009-07-11 19:10 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-07-11 04:25 . 2009-07-11 04:25 ——– d—–w- c:\documents and settings\bink\Application Data\SUPERAntiSpyware.com
2009-07-10 17:25 . 2009-07-10 17:25 ——– d—–w- C:\GameHouse Games
2009-07-10 17:24 . 2009-07-10 17:24 ——– d—–w- c:\program files\RealArcade
2009-07-09 23:24 . 2009-07-11 17:00 29 —-a-w- c:\windows\popcinfo.dat
2009-07-09 14:04 . 2009-07-11 19:38 ——– d—–w- c:\program files\MSN Games
2009-07-09 14:04 . 2009-07-11 19:07 ——– d—–w- c:\program files\Oberon Media
2009-07-07 00:52 . 2009-07-07 00:52 ——– d—–w- c:\program files\MSBuild
2009-07-07 00:48 . 2009-07-11 19:08 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-07-06 20:17 . 2009-07-06 20:17 ——– d—–w- c:\program files\Trend Micro
2009-07-06 19:24 . 2009-07-06 19:25 ——– d—–w- c:\program files\SpeedFan
2009-07-06 19:23 . 2009-07-06 19:23 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\Opera
2009-07-06 18:51 . 2009-07-06 18:51 ——– d—–w- c:\program files\Opera
2009-07-06 18:49 . 2009-07-06 18:50 ——– d—–w- c:\program files\Recuva
2009-07-06 18:49 . 2009-07-06 18:49 ——– d—–w- c:\program files\Defraggler
2009-07-06 18:45 . 2009-07-15 23:51 ——– d—–w- c:\program files\WinBar
2009-07-06 05:41 . 2008-10-16 19:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-07-06 05:41 . 2008-10-16 19:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-07-06 02:07 . 2009-07-15 23:54 ——– d—–w- c:\documents and settings\bink\Tracing
2009-07-06 02:06 . 2009-07-06 02:06 ——– d—–w- c:\program files\Microsoft
2009-07-06 02:05 . 2009-07-06 02:05 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-06 02:05 . 2009-07-06 02:06 ——– d—–w- c:\program files\Windows Live
2009-07-06 02:02 . 2009-07-06 02:02 ——– d—–w- c:\program files\Common Files\Windows Live
2009-07-06 01:58 . 2009-07-06 01:58 1244648 —-a-w- c:\documents and settings\bink\Application Data\MSNInstaller\msnauins.exe
2009-07-06 01:58 . 2009-07-06 01:58 ——– d—–w- c:\documents and settings\bink\Application Data\MSNInstaller
2009-07-04 17:07 . 2009-07-11 19:25 ——– d—–w- c:\documents and settings\bink\Application Data\uTorrent
2009-07-04 17:06 . 2009-07-04 17:06 ——– d—–w- c:\documents and settings\bink\Application Data\Aim
2009-07-04 16:55 . 2009-07-04 16:55 ——– d—–w- c:\documents and settings\bink\Application Data\Malwarebytes
2009-07-04 16:54 . 2009-06-17 16:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-04 16:54 . 2009-07-04 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-04 16:54 . 2009-06-17 16:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-04 16:54 . 2009-07-04 16:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-04 03:57 . 2009-07-04 03:57 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\Help
2009-07-01 14:47 . 2009-07-01 14:47 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-06-30 16:54 . 2009-06-30 16:54 ——– d—–w- c:\documents and settings\bink\Application Data\iWin
2009-06-30 16:54 . 2009-06-30 16:54 1245321 —-a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_FamilyFeud\IAF.dll
2009-06-30 14:58 . 2009-06-30 14:57 2052376 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-30 00:50 . 2009-04-05 19:26 8784 —-a-w- c:\documents and settings\bink\Application Data\Mozilla\Firefox\Profiles\v6dr6idi.default\extensions\[removed]\plugins\ractrlkeyhook.dll
2009-06-30 00:50 . 2009-02-19 16:38 2633728 —-a-w- c:\documents and settings\bink\Application Data\Mozilla\Firefox\Profiles\v6dr6idi.default\extensions\[removed]\plugins\npRACtrl.dll
2009-06-30 00:50 . 2009-06-23 16:06 245408 —-a-w- c:\documents and settings\bink\Application Data\Mozilla\Firefox\Profiles\v6dr6idi.default\extensions\[removed]\plugins\unicows.dll
2009-06-30 00:50 . 2009-04-05 19:26 71248 —-a-w- c:\documents and settings\bink\Application Data\Mozilla\Firefox\Profiles\v6dr6idi.default\extensions\[removed]\plugins\LMIProxyHelper.exe
2009-06-30 00:15 . 2009-07-11 19:10 ——– d—–w- c:\documents and settings\All Users\Application Data\River Past G5
2009-06-30 00:15 . 2009-06-30 00:15 ——– d—–w- c:\documents and settings\bink\Application Data\River Past G5
2009-06-30 00:08 . 2009-07-04 17:46 ——– d—–w- c:\program files\MP3 WAV Converter
2009-06-29 23:44 . 2008-10-17 01:35 83288 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-06-29 23:44 . 2008-10-17 01:35 23736 —-a-w- c:\windows\system32\LMImirr.dll
2009-06-29 23:44 . 2008-07-24 23:46 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-06-29 23:44 . 2008-07-24 23:45 10144 —-a-w- c:\windows\system32\drivers\LMImirr.sys
2009-06-29 23:44 . 2009-07-16 05:46 ——– d—–w- c:\program files\LogMeIn
2009-06-29 23:40 . 2009-06-29 23:40 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\LogMeIn
2009-06-29 23:40 . 2009-06-29 23:40 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-06-28 22:43 . 2009-06-28 22:43 ——– d—–w- c:\program files\TryMedia
2009-06-28 13:58 . 2009-07-11 19:09 ——– d—–w- c:\documents and settings\bink\Saved Games
2009-06-27 19:21 . 2009-06-27 19:21 ——– d—–w- c:\program files\EA GAMES
2009-06-27 17:34 . 2009-06-27 19:03 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\Axialis
2009-06-27 15:56 . 2009-06-27 15:56 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\Gamenauts
2009-06-27 14:52 . 2009-06-27 14:52 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\JollyBear
2009-06-27 14:52 . 2009-06-27 14:52 ——– d—–w- c:\documents and settings\All Users\Application Data\JollyBear
2009-06-27 13:48 . 2009-06-27 13:48 ——– d—–w- c:\documents and settings\bink\Application Data\Total Eclipse
2009-06-26 20:31 . 2009-06-26 20:31 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-06-26 20:16 . 2009-06-26 20:16 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-06-25 06:40 . 2009-06-26 03:45 ——– d—–w- c:\program files\Viewpoint
2009-06-25 06:40 . 2009-07-04 17:04 ——– d—–w- c:\program files\AOD
2009-06-25 06:39 . 2009-07-11 19:08 ——– d—–w- c:\program files\AIM
2009-06-25 04:02 . 2005-01-04 09:43 4682 —-a-w- c:\windows\system32\npptNT2.sys
2009-06-25 04:02 . 2009-06-25 04:02 ——– d—–w- c:\program files\Common Files\INCA Shared
2009-06-25 03:56 . 2009-06-25 03:56 ——– d—–w- C:\GamesCampus
2009-06-24 02:06 . 2009-06-24 02:06 ——– d—–w- c:\program files\Xvid
2009-06-24 02:06 . 2009-06-07 21:24 180224 —-a-w- c:\windows\system32\xvidvfw.dll
2009-06-24 02:06 . 2009-06-07 21:16 819200 —-a-w- c:\windows\system32\xvidcore.dll
2009-06-23 13:41 . 2009-06-23 13:41 ——– d-sh–w- c:\windows\ftpcache
2009-06-23 13:40 . 2009-06-23 13:40 1245321 —-a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_HideAndSecret\IAF.dll
2009-06-23 01:06 . 2009-06-23 01:06 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\Identities
2009-06-22 18:34 . 2009-06-22 18:34 ——– d—–w- c:\documents and settings\bink\Freeze Tag - Dream Machine
2009-06-22 17:27 . 2009-06-30 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2009-06-22 17:27 . 2009-06-22 17:27 1421449 —-a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_BurgerRush\IAF.dll
2009-06-22 14:01 . 2009-07-09 14:04 ——– d—–w- c:\documents and settings\bink\Local Settings\Application Data\Oberon Games
2009-06-22 13:57 . 2009-07-15 01:51 ——– d—–w- c:\program files\Yahoo! Games
2009-06-21 16:08 . 2009-07-11 19:10 ——– d—–w- c:\program files\GameHouse
2009-06-21 16:08 . 2009-07-14 10:12 ——– d–h–w- C:\$AVG8.VAULT$
2009-06-20 15:24 . 2009-07-06 18:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-06-20 15:19 . 2008-09-04 18:17 447752 —-a-r- c:\windows\system32\vp6vfw.dll
2009-06-20 15:19 . 2009-06-20 15:19 10134 —-a-r- c:\documents and settings\bink\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-20 15:19 . 2009-06-20 15:19 ——– d—–w- c:\program files\Microsoft WSE
2009-06-20 15:18 . 2006-09-28 21:05 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll
2009-06-20 15:18 . 2009-06-20 15:18 ——– d—–w- c:\windows\Logs
2009-06-20 15:12 . 2009-06-20 15:19 ——– d—–w- c:\program files\Electronic Arts
2009-06-20 14:31 . 2009-06-20 14:31 ——– d—–w- c:\documents and settings\bink\Application Data\JAM Software
2009-06-20 14:30 . 2009-06-20 14:30 ——– d—–w- c:\program files\JAM Software
2009-06-20 14:21 . 2009-06-20 14:21 ——– d—–w- c:\program files\PowerISO
2009-06-20 13:47 . 2009-06-20 13:47 ——– d—–w- c:\program files\SystemRequirementsLab

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 23:44 . 2008-10-29 01:22 ——– d—–w- c:\program files\Java
2009-07-11 19:42 . 2008-10-29 01:09 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-11 19:41 . 2008-10-29 01:37 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-11 19:35 . 2008-10-29 01:30 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-11 19:06 . 2008-10-29 01:18 ——– d—–w- c:\program files\Microsoft Works
2009-07-11 17:00 . 2008-10-29 01:09 ——– d—a-w- c:\documents and settings\All Users\Application Data\Temp
2009-07-07 00:54 . 2008-10-29 01:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-06 19:11 . 2008-10-29 01:37 ——– d—–w- c:\program files\BigFix
2009-07-06 19:11 . 2008-10-29 01:06 ——– d—–w- c:\program files\Google
2009-07-06 18:58 . 2008-10-29 01:10 ——– d—–w- c:\program files\CyberLink
2009-07-06 18:57 . 2008-10-29 01:10 36864 —-a-w- c:\documents and settings\All Users\Application Data\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2009-07-06 18:57 . 2008-10-29 01:10 53319 —-a-w- c:\documents and settings\All Users\Application Data\Temp\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
2009-07-04 17:43 . 2009-06-29 22:41 ——– d—–w- c:\program files\Free Audio Pack
2009-06-19 01:17 . 2009-06-19 01:17 ——– d—–w- c:\program files\iTunes
2009-06-19 01:17 . 2009-06-19 01:17 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-19 01:17 . 2009-06-19 01:17 ——– d—–w- c:\program files\iPod
2009-06-19 01:17 . 2009-06-19 01:16 ——– d—–w- c:\program files\Common Files\Apple
2009-06-19 01:17 . 2009-06-19 01:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-19 01:17 . 2009-06-19 01:17 ——– d—–w- c:\program files\Bonjour
2009-06-19 01:17 . 2009-06-19 01:16 ——– d—–w- c:\program files\QuickTime
2009-06-19 01:16 . 2009-06-19 01:16 ——– d—–w- c:\program files\Apple Software Update
2009-06-19 00:58 . 2008-10-29 00:51 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-19 00:26 . 2008-10-29 01:27 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-14 16:08 . 2009-07-03 19:33 57016 —-a-w- c:\windows\Fonts\TalvezAssim.ttf
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 15:42 . 2009-06-19 01:16 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 15:42 . 2009-06-19 01:16 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-05-07 15:32 . 2008-04-14 22:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2007-08-14 02:54 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2008-04-14 22:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2008-04-14 22:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-06-24 13:26 . 2009-07-12 21:16 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-15 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]

c:\documents and settings\bink\Start Menu\Programs\Startup\
WinBar.lnk - c:\program files\WinBar\WinBar.exe [2009-7-6 188928]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-18 23:50 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v3 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111v3 Smart Wizard.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/11/2009 7:04 PM 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [7/11/2009 3:01 PM 28544]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2009 6:50 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2009 6:50 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/18/2009 6:50 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/18/2009 6:50 PM 298776]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 12:13 PM 38144]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/29/2009 6:44 PM 47640]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 1:42 AM 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 6:03 AM 131072]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [12/28/2007 2:02 PM 287232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2009-07-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-07-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-LaunchApp - (no file)
Notify-LMIinit - LMIinit.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0609&m=el1200-06w
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0609&m=el1200-06w
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {F5D2AEB3-BBDB-4883-9379-55038DCB760D} = 208.67.222.222,208.67.220.220
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
FF - ProfilePath - c:\documents and settings\bink\Application Data\Mozilla\Firefox\Profiles\v6dr6idi.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\bink\Application Data\Mozilla\Firefox\Profiles\v6dr6idi.default\extensions\[removed]\plugins\npRACtrl.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-16 00:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(764)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-07-16 0:49
ComboFix-quarantined-files.txt 2009-07-16 05:49

Pre-Run: 32,087,879,680 bytes free
Post-Run: 32,142,344,192 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

347 — E O F — 2009-07-06 08:02
Unfortunately, firefox is still not responding, and pages occasionally aren't loading due to "the server has been reset" or similar errors. Also, this error message came up: C:\DOCUME~1\bink\LOCALS~1\Temp\WERa6a5.dir00\firefox.exe.mdmp C:\DOCUME~1\bink\LOCALS~1\Temp\WERa6a5.dir00\appcompat.txt Is the only solution to wipe and reinstall Windows? D:
faburizu,


  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    C:\DOCUME~1\bink\LOCALS~1\Temp\WERa6a5.dir00
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then please check for updates in your firefox. If still getting firefox problems. Try shutting off your add-ons and see how it goes.

Let me know what happens.
OTM isn't working. It ends explorer.exe and then nothing happens. I waited 45 minutes, and nothing. I disabled all my add-ons, and it's the same. I now know it's not just firefox, because the same happens with opera, IE, safari, anything else I use. It's in something else, and my friend thinks it may be a DNS hijack.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI